Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | Duplicate PostAI | 1/10/2026 | 1/10/2026 | The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Baja (2.7) | 0.32% | — | Duplicate PostAI | 21/8/2026 | 26/8/2026 | The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read the content, metadata and passwords of posts they are not allowed to access, including other users' private and draft content. | |
| Aplazada | Baja (2.7) | 0.30% | — | Duplicate PostAI | 21/8/2026 | 26/8/2026 | The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users with a delegated role to republish another user's password-protected post as publicly readable. | |
| Aplazada | Media (6.5) | 0.42% | — | Duplicate PostAI | 10/8/2026 | 26/8/2026 | The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary posts on the site, including those… | |
| Aplazada | Media (5.1) | 0.24% | — | Yoast Duplicate PostAI | 10/6/2026 | 23/7/2026 | Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to execute script when an administrator views the resulting notice. | |
| Aplazada | Media (5.1) | 0.15% | — | Yoast Duplicate PostAI | 10/6/2026 | 23/7/2026 | Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authenticated user into sending a request that sets the duplicate_post_show_notice site option, suppressing admin notices… | |
| Aplazada | Media (5.4) | 0.17% | — | Yoast Duplicate PostAI | 18/3/2026 | 17/6/2026 | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the clone_bulk_action_handler() and republish_request() functions in all versions up to, and including, 4.5. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (4.8) | 0.22% | — | Yoast Duplicate-postAI | 11/2/2026 | 17/6/2026 | Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces. | |
| Aplazada | Media (4.3) | 0.33% | — | Duplicate Post Page AND ANY Custom PostAI | 7/1/2025 | 17/6/2026 | The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.5 via the 'dpp_duplicate_as_draft' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially… | |
| Aplazada | Media (5.4) | 0.57% | — | Inqsys Technology Duplicate Post Page Menu AND Custom Post TypeAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Inqsys Technology Duplicate Post Page Menu & Custom Post Type allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Duplicate Post Page Menu & Custom Post Type: from n/a through 2.4.1. | |
| Aplazada | Media (6.3) | 0.40% | — | Muhammad Rehman Remove Duplicate PostsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Muhammad Rehman Remove Duplicate Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Remove Duplicate Posts: from n/a through 1.3.5. | |
| Modificada | Crítica (9.8) | 0.51% | — | Cleverplugins Delete Duplicate Posts | 19/12/2023 | 17/6/2026 | Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9. | |
| Modificada | Media (4.3) | 0.50% | — | Inqsys Duplicate Post Page Menu & Custom Post Type | 7/9/2023 | 17/6/2026 | The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access… | |
| Modificada | Media (4.3) | 0.61% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+6 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to Cross-Site Request Forgery to unauthorized installation of plugins due to a missing nonce check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.5) | 0.69% | — | Backupbliss Backup MigrationBackupbliss CloneCopy-delete-posts Duplicate PostInisev Enhanced Text Widget+7 | 28/7/2023 | 17/6/2026 | Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions,… | |
| Modificada | Alta (8.8) | 9.7% | — | Duplicate Post Project Duplicate Post | 19/11/2021 | 17/6/2026 | The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vulnerabilities occur when client supplied data is included within an SQL Query insecurely. SQL Injection can typically be exploited to read, modify and delete SQL table data. In many cases it also… | |
| Modificada | Crítica (9.8) | 1.8% | — | Duplicate Post Project Duplicate Post | 21/8/2019 | 17/6/2026 | The duplicate-post plugin before 2.6 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.91% | — | Duplicate Post Project Duplicate Post | 21/8/2019 | 17/6/2026 | The duplicate-post plugin before 2.6 for WordPress has XSS. |